Available Locations: Austin
We are seeking a highly skilled and experienced Insider Threat Tech Lead to join our dynamic and growing Security Threat Detection, Response and Emulation team. This critical role will be at the forefront of protecting our company from malicious and negligent insider activities. You will lead the technical aspects of our Insider Threat program, including investigations, threat hunting, and the development of cutting‑edge detections and responses.
This role requires a blend of technical expertise, regulatory and legal knowledge, investigative skills, and strong interpersonal communication. You will be a key point of contact and collaborator with our Privacy, Legal, GRC and HR teams, ensuring that all activities are conducted with the utmost care and in compliance with legal and ethical standards.
What you'll do
- Lead Insider Threat Digital Investigations:
- Conduct comprehensive technical investigations individually and partnering with incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.
- Collect, preserve, and analyze digital evidence from a variety of sources such as endpoints, network logs, cloud services, and email.
- Document all investigative steps and findings in a clear, concise, and defensible manner.
- Present findings to senior leadership and cross‑functional partners (Legal, HR, Privacy) professionally and objectively.
- Ensure regulatory, legal, and privacy requirements are met.
- Insider Threat Hunting:
- Proactively hunt for insider threats using security tools and data sources like SIEM, DLP, EDR, and UEBA.
- Develop and execute threat‑hunting hypotheses based on emerging threats and attack techniques.
- Correlate disparate data points to identify anomalous or suspicious user behaviors.
- Detection & Response Improvement:
- Collaborate closely with SIRT and Threat Detection teams to enhance insider‑threat detection capabilities.
- Design, develop, and implement new rules, alerts, and use cases in security tools.
- Evaluate and recommend technologies and processes to mature the Insider Threat program.
- Develop and refine response playbooks for various insider threat scenarios.
- Cross‑Functional Collaboration:
- Serve as the primary technical liaison for the Insider Threat program.
- Work with Legal, HR, and Privacy teams to ensure investigations respect employee privacy and legal guidelines.
- Provide technical expertise during policy development and incident response planning.
Required Qualifications
- 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations.
- Proven experience leading complex technical investigations and using forensic tools such as EnCase, FTK, X‑Ways, or open‑source alternatives.
- Deep understanding of security technologies such as SIEM, EDR, and UEBA data sources.
- Strong scripting and programming skills (Python, PowerShell) for automation and data analysis.
- Excellent written and verbal communication skills, able to explain technical concepts to non‑technical audiences.
- Experience working with legal and HR teams on sensitive employee‑related matters.
Preferred Qualifications
- Certifications such as GCIH, GCFA, GCTI, or similar.
- Experience with cloud‑based security and investigations (AWS, GCP, Azure).
- Prior experience in a tech product or fast‑paced startup environment.
- Knowledge of legal and regulatory frameworks related to data privacy and digital evidence (GDPR, CCPA).
- Experience handling legal/court evidence and presenting procedures.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. An offer of employment may be conditioned on your authorization to receive technology without export‑sponsorship.
Cloudflare is a proud equal‑opportunity employer. We are committed to providing equal employment opportunity for all people and cherish diversity and inclusiveness. All qualified applicants will be considered for employment without regard to race, color, religion, sex, gender, gender identity, sexual orientation, national origin, citizenship, age, disability, or any other protected basis. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. If you require an accommodation to apply, please let us know.
#J-18808-Ljbffr